Fun

News Feed - 2023-09-11 10:09:19

Brayden Lindrea7 hours agoLido assures LDO, stETH tokens remain safe despite flaw in token contractThe “fake deposit” attack enables bad actors to execute a transfer where the requested value is larger than what the user actually owns.2581 Total views21 Total sharesListen to article 0:00NewsJoin us on social networksEthereum staking protocol Lido Finance has assured both Lido DAO (LDO) and staked-Ether (stETH) tokens remain safe despite hackers allegedly exploiting a known security flaw in LDO’s token contract.


Lido didn’t confirm any exploits, but acknowledged the security flaw was known and reassured LDO and stETH funds remain safe in response to a Sept. 10 post by blockchain security firm SlowMist.


SlowMist said LDO’s flawed token contract allows bad actors to facilitate “fake deposit” attacks on exchanges because LDO’s token contract enables users to execute transactions even where they don’t have sufficient funds. This code deviates from the Ethereum Request for Comment 20 (ERC-20) token standard, according to SlowMist.


However, Lido Finance argued the flaw is built into all ERC-20 tokens — not just Lido’s LDO token:This behaviour is expected and conforms to the ERC20 token standard (see tweet below). Both LDO and stETH (and Lido governance) remain safe.

Lido token integration guides will be updated with LDO specifics to make this more visible shortly.— Lido (@LidoFinance) September 10, 2023


SlowMist said the “fake deposit” attacks came from LDO’s token contract executing transfers where the value is larger than what the user actually owns, triggering a false return as opposed to reverting the transaction. While the firm said Lido’s token contract has recently been exploited via this attack, no on-chain evidence was provided.


Cointelegraph reached out to SlowMist for comment but did not receive an immediate response.


Meanwhile, on-chain analyst “Hercules” explained on Sept. 10 that the security flaw may not be picked up by cryptocurrency exchanges.


SlowMist recommends LDO holders to also check the return values of the token contract transfers in addition to the success or failure of a transaction.


The blockchain security firm concluded that token contract implementations and behaviors vary by project and to conduct comprehensive testing before integrating any new tokens.


Related:Ethereum staking services agree to 22% limit of all validators


However, Lido highlighted in the official Ethereum Improvement Proposal document — co-authored by Vitalik Buterin in November 2015 — that both the “transfer” and “transferFrom” functions must return the transfer status and are only recommended to revert a transaction in exceptional cases.ERC20 token standard: https://t.co/YlrS1ZN6Fd

1) Both transfer and transferFrom are required to return transfer status and are only recommended to revert a tx in exceptional cases.

2) The standard says that a caller is obliged to check the return status (see 'Token methods'). pic.twitter.com/6KTcIyxo2F— Lido (@LidoFinance) September 10, 2023


To resolve the security flaw, Lido confirmed that the LDO token integration guides will soon be updated.


Collect this article as an NFTto preserve this moment in history and show your support for independent journalism in the crypto space.


Magazine:DeFi Dad, Hall of Flame: Ethereum is ‘woefully undervalued’ but growing more powerful# Altcoin# Security# Ethereum# Hackers# DAO# ERC-20# DeFi# Staking# Lido DAOAdd reactionAdd reactionRead moreHow to actually spend your Bitcoin, ExplainedCrypto VC: Risk and investment strategies with Shima CapitalHuman vs. AI: Who is better at crypto investing?

News Feed

Forcount crypto scheme promoters plead guilty to wire fraud conspiracy
Turner Wright2 hours agoForcount crypto scheme promoters plead guilty to wire fraud conspiracyOn July 22, two of the five individuals who allegedly stole $8.4 million from investors between 2017 and 2021 by promoting For
Crypto Biz: US dollar exposure via digital assets takes off
Ana Paula Pereira3 hours agoCrypto Biz: US dollar exposure via digital assets takes offThis week’s Crypto Biz explores Hashdex filing for a combined spot Bitcoin and Ether ETF, Coinbase’s pre-launch market, Ripple’
Bitcoin, Ethereum Technical Analysis: ETH Stays Above $2,900 as Traders Eye $3,000 Ceiling 
Bitcoin, Ethereum Technical Analysis: ETH Stays Above $2,900 as Traders Eye $3,000 Ceiling  Ethereum remained above $2,900 to start the week, as the world’s second largest
While Apecoin Reaches New Price Highs, Data Shows Top 100 APE Holders Control 52% of the Supply
While Apecoin Reaches New Price Highs, Data Shows Top 100 APE Holders Control 52% of the Supply During the last two weeks, statistics show the new crypto asset dedicated to the Bor
Terra Protocol Surpasses Binance Smart Chain in Terms of Value Locked in Defi
Terra Protocol Surpasses Binance Smart Chain in Terms of Value Locked in Defi The total value locked (TVL) in decentralized finance (defi) has rebounded in fiat value after sufferi
Coinbase Fined €3.3 Million in Netherlands, Exchange Considers Appeal
Coinbase Fined €3.3 Million in Netherlands, Exchange Considers Appeal The Dutch central bank has imposed a fine on crypto exchange Coinbase for providing services in the past wit
William Suberg13 hours agoBTC price won’t hit $100K before 2024 halving — Bitcoin investment execBitcoin halving data will not be reflected in the market for a year or more, says Jesse Myers.5798 Total views55 Total
Why Biden’s exit from the elections briefly pushed Bitcoin price to $68K
Zoltan Vardai10 hours agoWhy Biden’s exit from the elections briefly pushed Bitcoin price to $68KBiden’s exit from the presidential race helped Bitcoin recover, but analysts expect the decision to cause more uncertai
Q3 Crypto Volumes up by $155 Billion as Defi Hype Drives DEX Growth by 197%
Q3 Crypto Volumes up by $155 Billion as Defi Hype Drives DEX Growth by 197%The latest data from Coingecko shows that the combined trading volumes of cryptocurrency exchanges went up
Indian Government Updates Parliament on Cryptocurrency Bill and Investigations of Crypto Exchanges
Indian Government Updates Parliament on Cryptocurrency Bill and Investigations of Crypto Exchanges The government of India has provided some updates on its cryptocurrency bill and
Expert Calls On Ripple Community To Collectively Send XRP Price On 1,800x Rally To $1,000
Este artículo también está disponible en español. The idea of the XRP price reaching $1,000has once again gained traction as a social media platform X user called Drewski
China accessing high-level AI chips banned by the US: Report
Savannah Fortis12 hours agoChina accessing high-level AI chips banned by the US: ReportDocuments have surfaced revealing state-linked Chinese entities using Amazon cloud services or similar services to access advanced AI